Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27533

Опубликовано: 07 мая 2025
Источник: redhat
CVSS3: 4.9

Описание

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

A flaw was found in Apache ActiveMQ. This vulnerability allows denial of service by depleting process memory via unmarshalling OpenWire commands without proper size validation when not using mutual TLS connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2activemq-openwire-legacyFix deferred
Red Hat AMQ Broker 7activemq-openwire-legacyAffected
Red Hat build of Quarkusactivemq-openwire-legacyNot affected
Red Hat Data Grid 8activemq-openwire-legacyFix deferred
Red Hat Fuse 7activemq-openwire-legacyFix deferred
Red Hat Integration Camel K 1activemq-openwire-legacyFix deferred
Red Hat JBoss Enterprise Application Platform 7activemq-openwire-legacyNot affected
Red Hat JBoss Enterprise Application Platform 8activemq-openwire-legacyNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packactivemq-openwire-legacyNot affected
streams for Apache Kafkaactivemq-openwire-legacyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-789
https://bugzilla.redhat.com/show_bug.cgi?id=2364684ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS3: 7.5
nvd
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS3: 7.5
debian
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache Ac ...

CVSS3: 7.5
github
4 месяца назад

Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

CVSS3: 6.8
fstec
4 месяца назад

Уязвимость обработчика команд OpenWire программной платформы Apache ActiveMQ, позволяющая нарушителю вызвать отказ в обслуживании

4.9 Medium

CVSS3